Loading ...

Play interactive tourEdit tour

Windows Analysis Report Peixoto - QUOTATION LIST.exe

Overview

General Information

Sample Name:Peixoto - QUOTATION LIST.exe
Analysis ID:499570
MD5:0f129aa97048f7ec0557b211349a2ce0
SHA1:b597185c94fac60cd7e25db83bfb39ed07409289
SHA256:fcf3b27fdc54c53a1f7510abf8bdf748bd3199813d0294738feba29c7c1054d1
Tags:exeNanoCore
Infos:

Most interesting Screenshot:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Sigma detected: NanoCore
Detected Nanocore Rat
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Yara detected Nanocore RAT
Initial sample is a PE file and has a suspicious name
Writes to foreign memory regions
Machine Learning detection for sample
Allocates memory in foreign processes
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
Creates an undocumented autostart registry key
Machine Learning detection for dropped file
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Internet Provider seen in connection with other malware
Detected potential crypto function
Stores files to the Windows start menu directory
Contains long sleeps (>= 3 min)
Enables debug privileges
Creates a DirectInput object (often for capturing keystrokes)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Installs a raw input device (often for capturing keystrokes)
Sample file is different than original file name gathered from version info
PE file contains strange resources
Drops PE files
Detected TCP or UDP traffic on non-standard ports
Binary contains a suspicious time stamp
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)

Classification

Process Tree

  • System is w10x64
  • Peixoto - QUOTATION LIST.exe (PID: 5460 cmdline: 'C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe' MD5: 0F129AA97048F7EC0557B211349A2CE0)
    • Peixoto - QUOTATION LIST.exe (PID: 6572 cmdline: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe MD5: 0F129AA97048F7EC0557B211349A2CE0)
    • Peixoto - QUOTATION LIST.exe (PID: 6584 cmdline: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe MD5: 0F129AA97048F7EC0557B211349A2CE0)
  • cleanup

Malware Configuration

Threatname: NanoCore

{"Version": "1.2.2.0", "Mutex": "28a7a9fa-8b88-4ff1-be22-9ecea4e9", "Group": "T-C", "Domain1": "185.222.57.149", "Domain2": "127.0.0.1", "Port": 4557, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x59eb:$x1: NanoCore.ClientPluginHost
  • 0x5b48:$x2: IClientNetworkHost
00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x59eb:$x2: NanoCore.ClientPluginHost
  • 0x6941:$s3: PipeExists
  • 0x5be1:$s4: PipeCreated
  • 0x5a05:$s5: IClientLoggingHost
00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x37de5:$x1: NanoCore.ClientPluginHost
  • 0x5fe05:$x1: NanoCore.ClientPluginHost
  • 0x37e22:$x2: IClientNetworkHost
  • 0x5fe42:$x2: IClientNetworkHost
  • 0x3b955:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
  • 0x63975:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
    00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
    • 0x37b4d:$a: NanoCore
    • 0x37b5d:$a: NanoCore
    • 0x37d91:$a: NanoCore
    • 0x37da5:$a: NanoCore
    • 0x37de5:$a: NanoCore
    • 0x5fb6d:$a: NanoCore
    • 0x5fb7d:$a: NanoCore
    • 0x5fdb1:$a: NanoCore
    • 0x5fdc5:$a: NanoCore
    • 0x5fe05:$a: NanoCore
    • 0x37bac:$b: ClientPlugin
    • 0x37dae:$b: ClientPlugin
    • 0x37dee:$b: ClientPlugin
    • 0x5fbcc:$b: ClientPlugin
    • 0x5fdce:$b: ClientPlugin
    • 0x5fe0e:$b: ClientPlugin
    • 0x37cd3:$c: ProjectData
    • 0x5fcf3:$c: ProjectData
    • 0x386da:$d: DESCrypto
    • 0x606fa:$d: DESCrypto
    • 0x400a6:$e: KeepAlive
    Click to see the 49 entries

    Unpacked PEs

    SourceRuleDescriptionAuthorStrings
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x605:$x1: NanoCore.ClientPluginHost
    • 0x63e:$x2: IClientNetworkHost
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
    • 0x605:$x2: NanoCore.ClientPluginHost
    • 0x720:$s4: PipeCreated
    • 0x61f:$s5: IClientLoggingHost
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x2205:$x1: NanoCore.ClientPluginHost
    • 0x223e:$x2: IClientNetworkHost
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
    • 0x2205:$x2: NanoCore.ClientPluginHost
    • 0x2320:$s4: PipeCreated
    • 0x221f:$s5: IClientLoggingHost
    16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x6da5:$x1: NanoCore.ClientPluginHost
    • 0x6dd2:$x2: IClientNetworkHost
    Click to see the 135 entries

    Sigma Overview

    AV Detection:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    E-Banking Fraud:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    Stealing of Sensitive Information:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    Remote Access Functionality:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Found malware configurationShow sources
    Source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmpMalware Configuration Extractor: NanoCore {"Version": "1.2.2.0", "Mutex": "28a7a9fa-8b88-4ff1-be22-9ecea4e9", "Group": "T-C", "Domain1": "185.222.57.149", "Domain2": "127.0.0.1", "Port": 4557, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}
    Multi AV Scanner detection for submitted fileShow sources
    Source: Peixoto - QUOTATION LIST.exeVirustotal: Detection: 25%Perma Link
    Multi AV Scanner detection for domain / URLShow sources
    Source: 185.222.57.149Virustotal: Detection: 5%Perma Link
    Multi AV Scanner detection for dropped fileShow sources
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeVirustotal: Detection: 25%Perma Link
    Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeVirustotal: Detection: 25%Perma Link
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR
    Machine Learning detection for sampleShow sources
    Source: Peixoto - QUOTATION LIST.exeJoe Sandbox ML: detected
    Machine Learning detection for dropped fileShow sources
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJoe Sandbox ML: detected
    Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJoe Sandbox ML: detected
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpackAvira: Label: TR/Dropper.MSIL.Gen7
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpackAvira: Label: TR/NanoCore.fadte
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpackAvira: Label: TR/NanoCore.fadte
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\MyNanoCore RemoteScripting\MyClientPlugin\obj\Debug\MyClientPluginNew.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp
    Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49751 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49752 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49773 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49779 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49780 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49781 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49782 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49783 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49801 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49813 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49814 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49815 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49816 -> 185.222.57.149:4557
    C2 URLs / IPs found in malware configurationShow sources
    Source: Malware configuration extractorURLs: 127.0.0.1
    Source: Malware configuration extractorURLs: 185.222.57.149
    Source: Joe Sandbox ViewASN Name: ROOTLAYERNETNL ROOTLAYERNETNL
    Source: global trafficTCP traffic: 192.168.2.7:49751 -> 185.222.57.149:4557
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpString found in binary or memory: http://google.com
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000002.330286689.000000000073B000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmpBinary or memory string: RegisterRawInputDevices

    E-Banking Fraud:

    barindex
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR

    System Summary:

    barindex
    Malicious sample detected (through community Yara rule)Show sources
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.5cb0000.15.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7254c9f.30.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.725e8a4.31.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71b0000.21.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45f0a04.10.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e6dff.9.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71f0000.24.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.505641453.00000000046D8000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Initial sample is a PE file and has a suspicious nameShow sources
    Source: initial sampleStatic PE information: Filename: Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.5cb0000.15.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.5cb0000.15.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7254c9f.30.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7254c9f.30.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.725e8a4.31.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.725e8a4.31.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71b0000.21.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71b0000.21.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45f0a04.10.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45f0a04.10.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e6dff.9.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e6dff.9.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71f0000.24.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71f0000.24.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.505641453.00000000046D8000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354ACF
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02353661
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02352E50
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354A7D
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354AAB
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023552E7
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023548C1
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354930
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_0235491A
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_0235495E
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_0235494D
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023549B3
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354E34
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354C1D
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354CF4
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354D20
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02352510
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_058EE480
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_058EE471
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_058EBBD4
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A3F5F8
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A39788
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A335A8
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A3A580
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilename vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000003.325328970.00000000007A6000.00000004.00000001.sdmpBinary or memory string: OriginalFilenamenow-ConsoleApp13.exeB vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameZuqohptuwpijwgcwqzv.dll" vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilename vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilename vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameMyClientPlugin.dll@ vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507190685.00000000067D0000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameLzma#.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameSecurityClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameManagementClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameNanoCoreBase.dll< vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameMyClientPluginNew.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameFileBrowserClient.dllT vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameMyClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameNanoCoreStressTester.dll< vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameNetworkClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameToolsClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameAForge.Video.DirectShow.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameNAudio.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameSurveillanceClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameCoreClientPlugin.dll8 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameSurveillanceExClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.500613906.00000000016FA000.00000004.00000020.sdmpBinary or memory string: OriginalFilenameclr.dllT vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilenamenow-ConsoleApp13.exeB vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: zhrtgdis.exe.0.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: Peixoto - QUOTATION LIST.exe.0.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: zhrtgdis.exe.0.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: Peixoto - QUOTATION LIST.exe.0.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: Peixoto - QUOTATION LIST.exeVirustotal: Detection: 25%
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile read: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Source: unknownProcess created: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe 'C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe'
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: classification engineClassification label: mal100.troj.evad.winEXE@5/9@0/1
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{28a7a9fa-8b88-4ff1-be22-9ecea4e92a97}
    Source: Peixoto - QUOTATION LIST.exe, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: zhrtgdis.exe.0.dr, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: Peixoto - QUOTATION LIST.exe.0.dr, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: 0.0.Peixoto - QUOTATION LIST.exe.20000.0.unpack, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: 0.2.Peixoto - QUOTATION LIST.exe.20000.0.unpack, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: 15.0.Peixoto - QUOTATION LIST.exe.10000.0.unpack, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
    Source: Peixoto - QUOTATION LIST.exeStatic file information: File size 1203200 > 1048576
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\MyNanoCore RemoteScripting\MyClientPlugin\obj\Debug\MyClientPluginNew.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp
    Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp

    Data Obfuscation:

    barindex
    .NET source code contains potential unpackerShow sources
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.cs.Net Code: #=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA= System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecUu003d.cs.Net Code: #=qKU0J1fiP8KA33eFK1owekQ== System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: 0xAEA5775B [Mon Nov 6 22:59:39 2062 UTC]
    Source: initial sampleStatic PE information: section name: .text entropy: 7.99870340819
    Source: initial sampleStatic PE information: section name: .text entropy: 7.99870340819
    Source: initial sampleStatic PE information: section name: .text entropy: 7.99870340819
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.csHigh entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs='
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.csHigh entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK'
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to dropped file
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJump to dropped file

    Boot Survival:

    barindex
    Creates an undocumented autostart registry key Show sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeKey value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders StartupJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe\:Zone.Identifier:$DATAJump to behavior

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Hides that the sample has been downloaded from the Internet (zone.identifier)Show sources
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeFile opened: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe:Zone.Identifier read attributes | delete
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeRegistry key monitored for changes: HKEY_CURRENT_USER_Classes
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe TID: 3264Thread sleep time: -922337203685477s >= -30000s
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe TID: 6676Thread sleep time: -4611686018427385s >= -30000s
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: threadDelayed 4459
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: threadDelayed 3846
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: foregroundWindowGot 526
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: foregroundWindowGot 614
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information queried: ProcessInformation
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501089724.0000000001775000.00000004.00000020.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllA
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess token adjusted: Debug
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess token adjusted: Debug
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory allocated: page read and write | page guard

    HIPS / PFW / Operating System Protection Evasion:

    barindex
    Writes to foreign memory regionsShow sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 400000
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 402000
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 420000
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 422000
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 113C008
    Allocates memory in foreign processesShow sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory allocated: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 400000 protect: page execute and read and write
    Injects a PE file into a foreign processesShow sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 400000 value starts with: 4D5A
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: uProgram Manager
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507484711.000000000706B000.00000004.00000001.sdmpBinary or memory string: Program Manager#
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507393672.0000000006B6C000.00000004.00000001.sdmpBinary or memory string: Program Manager
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: Progman
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507170704.00000000067CC000.00000004.00000001.sdmpBinary or memory string: Program Managerram Manager
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.503827465.0000000003755000.00000004.00000001.sdmpBinary or memory string: Program Manager|$
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.503113331.000000000356F000.00000004.00000001.sdmpBinary or memory string: Program ManagerHa_l(
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: Progmanlock
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.504994665.0000000003A47000.00000004.00000001.sdmpBinary or memory string: Program Manager4
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.504994665.0000000003A47000.00000004.00000001.sdmpBinary or memory string: Program Manager@lp
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe VolumeInformation
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe VolumeInformation
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct

    Stealing of Sensitive Information:

    barindex
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR

    Remote Access Functionality:

    barindex
    Detected Nanocore RatShow sources
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpString found in binary or memory: NanoCore.ClientPluginHost
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpString found in binary or memory: NanoCore.ClientPluginHost
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCoreBase.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainNanoCoreBaseClientPluginCommandHandlerResourcesNanoCoreBase.My.ResourcesMySettingsMySettingsPropertyCommandsMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostSendCommandparamsInitializePluginNanoCore.ClientPluginIClientNetwork_networkhost_loggingHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketHandleCommandHandleCommandOpenWebsiteHandleCommandMessageBoxSwapMouseButtonfSwapuser32.dllHandleCommandMouseSwapHandleCommandMouseUnswapmciSendStringlpszCommandlpszReturnStringcchReturnLengthhwndCallbackwinmm.dllmciSendStringAHandleCommandCDTrayHandleCommandCDTrayCloseSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CultureValueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsEnumvalue__OpenWebsiteMessageBoxCDTrayCDTrayCloseMouseSwapMouseUnswapSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeSendToServerParamArrayAttributeStringProcessStartSystem.Windows.FormsDialogResultShowConversionsReferenceEqualsSystem.ReflectionAssemblyget_AssemblyCompilerGeneratedAttributeSettingsBaseSynchronizedNanoCoreBase.Resources.resourcesDebuggableAttributeDebuggingModesCompilationRelaxationsAttributeRuntimeCompatibilityAttributeAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeNanoCoreBase.dll+set CDAudio door open/set CDAudio door closed-NanoCoreBase.Resources3
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationFileBrowserClient.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainFileBrowserClientClientPluginCommandHandlersResourcesFileBrowserClient.My.ResourcesMySettingsMySettingsPropertyFunctionsCommandTypesMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostCurrentDirectoryInitializePluginNanoCore.ClientPluginIClientNetwork_loggingHost_networkHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketparamsHandleCreateDirectoryremoteDirHandleDeleteFileremoteFileisDirectoryHandleOpenFileHandleReceiveFilelocalFileHandleRenameFilenewFileNameHandleSetCurrentDirectorypathHandleDeleteHandleDownloadHandleDrivesHandleFilesHandleGetCurrentDirectoryHandleMachineNameHandleOpenHandleSetCurrentDirectoryPacketHandleUploadHandleRenameHandleCreateSendCurrentDirectorySendDrivesSendFileSendFilesSendMachineNameSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CulturevalueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsSystem.Collections.GenericList`1RemoteFilesRemoteFoldersRemoteDrivesEnumerateRemoteFilesEnumerateRemoteDrivesLogMessagemessageEnumvalue__MachineNameDrivesFilesGetCurrentDirectorySetCurrentDirectoryDownloadUploadOpenDeleteCreateDirectoryRenameSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeEnvironmentSpecialFolderGetFolderPathStringFormatSystem.IODirectoryDirectoryInfoProjectDataExceptionSetProjectErrorClearProjectErrorFileLogClientExceptionProcessStartConvertFromBase64StringWriteAllBytesMoveSendToServerConversionsToBooleanInt32NewLateBindingLateIndexGetEnumeratorEmptyGetEnumeratorget_CurrentTrimConcatMoveNextIDisposableDisposeReadAllBytesToBase64StringIsNullOrEmptyget_MachineNameToUpperget_UserNameReferenceEqualsSystem.ReflectionAssemblyget_AssemblyCompilerGeneratedAttributeSettingsBaseSynchronizedFileInfoFileSystemInfoget_FullNameContainsGetDirectoriesget_NameAddGetF
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationMyClientPlugin.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainMyClientPluginClientPluginMiscCommandHandlerCommandTypeMiscCommandMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostInitializePluginNanoCore.ClientPluginIClientNetwork_loggingHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketparamsHandleMiscCommandHandleMiscCommandMessageInterpretRecievedcommandtodoloopkeysEnumvalue__MessageStringExceptionMicrosoft.VisualBasic.CompilerServicesOperatorsCompareStringServerComputerMicrosoft.VisualBasic.MyServicesRegistryProxyget_RegistryMicrosoft.Win32RegistryKeyget_LocalMachineConcatInt32SetValueProjectDataSetProjectErrorClearProjectErrorget_LengthStandardModuleAttributeSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeDebuggableAttributeDebuggingModesCompilationRelaxationsAttributeRuntimeCompatibilityAttributeSystem.ReflectionAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeMyClientPlugin.dll'DisableWebcamLights
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCoreStressTester.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainNanoCoreStressTesterClientPluginHTTPFloodSlowLorisSYNFloodTCPNanoCoreStressTester.FloodUDPSendSynCommandHandlerResourcesNanoCoreStressTester.My.ResourcesMySettingsMySettingsPropertyCommandsMethodsMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostIClientDataHostDataHostClientGUIDSendCommandparamsInitializePluginNanoCore.ClientPluginIClientNetwork_networkhost_loggingHost_DataHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketStartHostToAttackArrayUploadDataSiteUserAgentRefererValuesGeneratecodelengthSystem.ThreadingThreadThreadsPortToAttackTimeToAttackThreadstoUseThreadsEndedattacksAttackRunningFloodnewHostnewPortnewTimenewThreadslolStopSlowlorisStressThreadStart_floodingJob_floodingThreadSystem.NetIPEndPoint_ipEo_synClassHostIsEnabledPortSuperSynSocketsStartSuperSynStopSuperSynSystem.Net.SocketsSocketClientIPPacketsPacketSizeMaxPacketsStopFloodmPacketspSize_sockipEosuperSynSockets__1IAsyncResultOnConnectarSendFloodingstopHTTPBytesSentSYNConnectionsHTTPDataSentMethodTargetAddressTargetStatusupdateBytesnewSYNFloodHandleDDOSCommandHandleStopCommandSystem.TimersElapsedEventArgsbytesTimerElapsedsourceeHandleHTTPCommandHandleSlowlorisCommandHandleTCPCommandHandleUDPCommandHandleSYNCommandSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CultureValueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsEnumvalue__sendStressCommandupdateStatusColumnstopStressCommandHTTPSlowlorisSYNSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeExceptionSendToServerProjectDataSetProjectErrorClearProjectErrorTimerNanoCoreIClientNameObjectCollectionget_VariablesGetValueset_Intervalset_EnabledElapsedEventHandleradd_ElapsedParamArrayAttributeRandomGuidStringIsNullOrEmptyArgumentNullExceptionArgumentOutOfRangeExce
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCore.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1IClientNetworkNanoCore.ClientPluginIClientDataIClientAppIClientDataHostNanoCore.ClientPluginHostIClientNetworkHostIClientUIHostIClientLoggingHostIClientAppHostIClientNameObjectCollectionNanoCoreIClientReadOnlyNameObjectCollectionClientInvokeDelegateMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceReadPacketpipeNameparamsPipeCreatedPipeClosedConnectionStateChangedconnectedConnectionFailedhostportBuildingHostCacheVariableChangednameClientSettingChangedPluginUninstallingClientUninstallingget_Variablesget_ClientSettingsget_BuilderSettingsVariablesClientSettingsBuilderSettingsget_ConnectedClosePipePipeExistsRebuildHostCacheAddHostEntryDisconnectSendToServercompressConnectedInvokemethodstateLogClientMessagemessageExceptionLogClientExceptionexsiteRestartShutdownDisableProtectionRestoreProtectionUninstallEntryExistsSystem.Collections.GenericKeyValuePair`2GetEntriesGetValuedefaultValueSetValuevalueRemoveValueMulticastDelegateTargetObjectTargetMethodIAsyncResultAsyncCallbackBeginInvokeDelegateCallbackDelegateAsyncStateEndInvokeDelegateAsyncResultSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeParamArrayAttributeCompilationRelaxationsAttributeRuntimeCompatibilityAttributeSystem.ReflectionAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeClientPluginClientPlugin.dll
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management Instrumentation1Registry Run Keys / Startup Folder11Process Injection312Masquerading1Input Capture21Query Registry1Remote ServicesInput Capture21Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsRegistry Run Keys / Startup Folder11Disable or Modify Tools1LSASS MemorySecurity Software Discovery111Remote Desktop ProtocolArchive Collected Data11Exfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Virtualization/Sandbox Evasion21Security Account ManagerProcess Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationRemote Access Software1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection312NTDSVirtualization/Sandbox Evasion21Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol1SIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptDeobfuscate/Decode Files or Information1LSA SecretsApplication Window Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
    Replication Through Removable MediaLaunchdRc.commonRc.commonHidden Files and Directories1Cached Domain CredentialsSystem Information Discovery12VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
    External Remote ServicesScheduled TaskStartup ItemsStartup ItemsObfuscated Files or Information1DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
    Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobSoftware Packing13Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
    Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Timestomp1/etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    Peixoto - QUOTATION LIST.exe26%VirustotalBrowse
    Peixoto - QUOTATION LIST.exe100%Joe Sandbox ML

    Dropped Files

    SourceDetectionScannerLabelLink
    C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe100%Joe Sandbox ML
    C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe100%Joe Sandbox ML
    C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe26%VirustotalBrowse
    C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe26%VirustotalBrowse

    Unpacked PE Files

    SourceDetectionScannerLabelLinkDownload
    16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack100%AviraTR/Dropper.MSIL.Gen7Download File
    16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack100%AviraTR/NanoCore.fadteDownload File
    16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack100%AviraTR/NanoCore.fadteDownload File

    Domains

    No Antivirus matches

    URLs

    SourceDetectionScannerLabelLink
    127.0.0.10%VirustotalBrowse
    127.0.0.10%Avira URL Cloudsafe
    185.222.57.1496%VirustotalBrowse
    185.222.57.1490%Avira URL Cloudsafe

    Domains and IPs

    Contacted Domains

    No contacted domains info

    Contacted URLs

    NameMaliciousAntivirus DetectionReputation
    127.0.0.1true
    • 0%, Virustotal, Browse
    • Avira URL Cloud: safe
    unknown
    185.222.57.149true
    • 6%, Virustotal, Browse
    • Avira URL Cloud: safe
    unknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    http://google.comPeixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpfalse
      high

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      185.222.57.149
      unknownNetherlands
      51447ROOTLAYERNETNLtrue

      General Information

      Joe Sandbox Version:33.0.0 White Diamond
      Analysis ID:499570
      Start date:08.10.2021
      Start time:16:08:18
      Joe Sandbox Product:CloudBasic
      Overall analysis duration:0h 10m 2s
      Hypervisor based Inspection enabled:false
      Report type:light
      Sample file name:Peixoto - QUOTATION LIST.exe
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
      Number of analysed new started processes analysed:25
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • HDC enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal100.troj.evad.winEXE@5/9@0/1
      EGA Information:Failed
      HDC Information:
      • Successful, ratio: 0.1% (good quality ratio 0.1%)
      • Quality average: 84.1%
      • Quality standard deviation: 10.6%
      HCA Information:
      • Successful, ratio: 99%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Adjust boot time
      • Enable AMSI
      • Found application associated with file extension: .exe
      Warnings:
      Show All
      • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
      • TCP Packets have been reduced to 100
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe
      • Excluded IPs from analysis (whitelisted): 95.100.216.89, 20.82.209.183, 20.54.110.249, 40.112.88.60, 2.20.178.24, 2.20.178.33
      • Excluded domains from analysis (whitelisted): iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, neu-displaycatalogrp.useroor.bigcatalog.commerce.microsoft.com, ris-prod.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, e1723.g.akamaiedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, ris.api.iris.microsoft.com, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtAllocateVirtualMemory calls found.

      Simulations

      Behavior and APIs

      TimeTypeDescription
      16:09:56API Interceptor655x Sleep call for process: Peixoto - QUOTATION LIST.exe modified

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      185.222.57.149MERMAID SUBSEA - purchase order RX86404382953.exeGet hashmaliciousBrowse

        Domains

        No context

        ASN

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        ROOTLAYERNETNLSecuriteInfo.com.Trojan.Win32.Save.a.20322.exeGet hashmaliciousBrowse
        • 45.137.22.115
        PaymentAdvice.exeGet hashmaliciousBrowse
        • 185.222.58.151
        PI009876789.exeGet hashmaliciousBrowse
        • 185.222.58.154
        Proforma invoice Shipping documents.exeGet hashmaliciousBrowse
        • 45.137.22.91
        Payment_Advice.exeGet hashmaliciousBrowse
        • 45.137.22.115
        PO. 2100002.xlsxGet hashmaliciousBrowse
        • 185.222.57.162
        2WK7SGkGVZ.exeGet hashmaliciousBrowse
        • 45.137.22.91
        PO1038845621.exeGet hashmaliciousBrowse
        • 45.137.22.70
        SecuriteInfo.com.Suspicious.Win32.Save.a.24632.exeGet hashmaliciousBrowse
        • 45.137.22.115
        Application Copy.exeGet hashmaliciousBrowse
        • 45.137.22.70
        Swift Copy.xlsxGet hashmaliciousBrowse
        • 185.222.57.85
        pre-shipment docs pdf.exeGet hashmaliciousBrowse
        • 45.137.22.131
        SOA_SEPT.exeGet hashmaliciousBrowse
        • 45.137.22.115
        MERMAID SUBSEA - purchase order RX86404382953.exeGet hashmaliciousBrowse
        • 185.222.57.149
        Application copy.exeGet hashmaliciousBrowse
        • 45.137.22.70
        New Purchase Order# 4502369263.exeGet hashmaliciousBrowse
        • 45.137.22.142
        swift0098765.exeGet hashmaliciousBrowse
        • 45.137.22.115
        bthGMpTA2L.exeGet hashmaliciousBrowse
        • 185.222.58.118
        New Order PO200305-01.exeGet hashmaliciousBrowse
        • 185.222.58.118
        PO. 2100002.xlsxGet hashmaliciousBrowse
        • 185.222.57.162

        JA3 Fingerprints

        No context

        Dropped Files

        No context

        Created / dropped Files

        C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Peixoto - QUOTATION LIST.exe.log
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:ASCII text, with CRLF line terminators
        Category:modified
        Size (bytes):425
        Entropy (8bit):5.340009400190196
        Encrypted:false
        SSDEEP:12:Q3La/KDLI4MWuPk21OKbbDLI4MWuPJKiUrRZ9I0ZKhav:ML9E4Ks2wKDE4KhK3VZ9pKhk
        MD5:CC144808DBAF00E03294347EADC8E779
        SHA1:A3434FC71BA82B7512C813840427C687ADDB5AEA
        SHA-256:3FC7B9771439E777A8F8B8579DD499F3EB90859AD30EFD8A765F341403FC7101
        SHA-512:A4F9EB98200BCAF388F89AABAF7EA57661473687265597B13192C24F06638C6339A3BD581DF4E002F26EE1BA09410F6A2BBDB4DA0CD40B59D63A09BAA1AADD3D
        Malicious:true
        Reputation:moderate, very likely benign file
        Preview: 1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..
        C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
        Category:dropped
        Size (bytes):1203200
        Entropy (8bit):7.928918657272288
        Encrypted:false
        SSDEEP:24576:Qi4th4HdHtaqrbvYfCxkRPaGynuJ4Bk0xdh1HVsx+aV3gyGw:P4tCvaqx0Ht+Bk0DNswq3g8
        MD5:0F129AA97048F7EC0557B211349A2CE0
        SHA1:B597185C94FAC60CD7E25DB83BFB39ED07409289
        SHA-256:FCF3B27FDC54C53A1F7510ABF8BDF748BD3199813D0294738FEBA29C7C1054D1
        SHA-512:0780847D48DDF9336633665560185E58C60BFD516D7CEB2139DE897C526E3D23236667A7BCC199009C37E1D8B153C40377D9717C51F97450967297F9D3BA759A
        Malicious:true
        Antivirus:
        • Antivirus: Joe Sandbox ML, Detection: 100%
        • Antivirus: Virustotal, Detection: 26%, Browse
        Reputation:low
        Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[w................0......~........... ........@.. ....................................@.....................................O.......xz........................................................................... ............... ..H............text...4.... ...................... ..`.rsrc...xz.......|..................@..@.reloc...............Z..............@..B........................H.......$&...............>...............................................0..+....... .......+..(...........X...2.(.........&..*.........''.......0..H.......(....o.....+!..(......r...p .......o....&..&....(....-...........o.....*.........+...........9.......0..U.......r...prS..prW..p(....(....rY..p ............%.(....(.....o....t.....s....%.o....o....*....0..Z.......( ...rc..po!....s"....s#....o$......o%.....o&....o'.......io(.......,..o.....o)...s*...z.*..........-C..........
        C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe:Zone.Identifier
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):26
        Entropy (8bit):3.95006375643621
        Encrypted:false
        SSDEEP:3:ggPYV:rPYV
        MD5:187F488E27DB4AF347237FE461A079AD
        SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
        SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
        SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
        Malicious:true
        Reputation:high, very likely benign file
        Preview: [ZoneTransfer]....ZoneId=0
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\catalog.dat
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:data
        Category:dropped
        Size (bytes):2088
        Entropy (8bit):7.024371743172393
        Encrypted:false
        SSDEEP:48:Ik/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrw8:flC0IlC0IlC0IlC0IlC0IlC0IlC0IlCe
        MD5:0D6805D12813A857D50D42D6EE2CCAB0
        SHA1:78D83F009D842F21FE2AB0EAFFD00E5AAD1776F4
        SHA-256:182E0F8AA959549D61C66D049645BA8445D86AEAD2B8C3552A9836FA1E5BD484
        SHA-512:5B29496F3AB3CCB915CF37042F4956BB00E577B5F15457A5A739BE1BD50C481FB7E3297EED575DCA7A7BD30ECBC140DD3666CD7DEDD25DFB7AEB41A1B5BEDA4A
        Malicious:false
        Reputation:moderate, very likely benign file
        Preview: Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:Non-ISO extended-ASCII text, with no line terminators
        Category:dropped
        Size (bytes):8
        Entropy (8bit):3.0
        Encrypted:false
        SSDEEP:3:5v8:G
        MD5:05D3210DC0F332DAC884A349CADDF7D9
        SHA1:7F6BCF10E578609F26A193EA92E72D57AE5EABC8
        SHA-256:384569455A5A7717A1CF73331CD40A9B2CE31AE8F4915351AA1FD8425E3B4C72
        SHA-512:DEEB972E54621868049FCA22E406B42F83C10305972DDEF7D9ED061F7DE90C3BBC12229A1477B0AEA0538847B2451C7211CE1A275508270F09CDED8525FDBA49
        Malicious:true
        Reputation:low
        Preview: ).....H
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\settings.bin
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:data
        Category:dropped
        Size (bytes):40
        Entropy (8bit):5.153055907333276
        Encrypted:false
        SSDEEP:3:9bzY6oRDT6P2bfVn1:RzWDT621
        MD5:4E5E92E2369688041CC82EF9650EDED2
        SHA1:15E44F2F3194EE232B44E9684163B6F66472C862
        SHA-256:F8098A6290118F2944B9E7C842BD014377D45844379F863B00D54515A8A64B48
        SHA-512:1B368018907A3BC30421FDA2C935B39DC9073B9B1248881E70AD48EDB6CAA256070C1A90B97B0F64BBE61E316DBB8D5B2EC8DBABCD0B0B2999AB50B933671ECB
        Malicious:false
        Reputation:moderate, very likely benign file
        Preview: 9iH...}Z.4..f.~a........~.~.......3.U.
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\storage.dat
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:data
        Category:dropped
        Size (bytes):327432
        Entropy (8bit):7.99938831605763
        Encrypted:true
        SSDEEP:6144:oX44S90aTiB66x3Pl6nGV4bfD6wXPIZ9iBj0UeprGm2d7Tm:LkjYGsfGUc9iB4UeprKdnm
        MD5:7E8F4A764B981D5B82D1CC49D341E9C6
        SHA1:D9F0685A028FB219E1A6286AEFB7D6FCFC778B85
        SHA-256:0BD3AAC12623520C4E2031C8B96B4A154702F36F97F643158E91E987D317B480
        SHA-512:880E46504FCFB4B15B86B9D8087BA88E6C4950E433616EBB637799F42B081ABF6F07508943ECB1F786B2A89E751F5AE62D750BDCFFDDF535D600CF66EC44E926
        Malicious:false
        Preview: pT..!..W..G.J..a.).@.i..wpK.so@...5.=.^..Q.oy.=e@9.B...F..09u"3.. 0t..RDn_4d.....E...i......~...|..fX_...Xf.p^......>a..$...e.6:7d.(a.A...=.)*.....{B.[...y%.*..i.Q.<..xt.X..H.. ..HF7g...I.*3.{.n....L.y;i..s-....(5i...........J.5b7}..fK..HV..,...0.... ....n.w6PMl.......v."".v.......#..X.a....../...cC...i..l{>5n.._+.e.d'...}...[..../...D.t..GVp.zz......(...o......b...+`J.{....hS1G.^*I..v&.jm.#u..1..Mg!.E..U.T.....6.2>...6.l.K.w"o..E..."K%{....z.7....<...,....]t.:.....[.Z.u...3X8.QI..j_.&..N..q.e.2...6.R.~..9.Bq..A.v.6.G..#y.....O....Z)G...w..E..k(....+..O..........Vg.2xC......O...jc.....z..~.P...q../.-.'.h.._.cj.=..B.x.Q9.pu.|i4...i...;O...n.?.,. ....v?.5}.OY@.dG|<.._[.69@.2..m..I..oP=...xrK.?............b..5....i&...l.c\b}..Q..O+.V.mJ.....pz....>F.......H...6$...d...|m...N..1.R..B.i..........$....$........CY}..$....r.....H...8...li.....7 P......?h....R.iF..6...q(.@LI.s..+K.....?m..H....*. l..&<}....`|.B....3.....I..o...u1..8i=.z.W..7
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
        Category:dropped
        Size (bytes):1203200
        Entropy (8bit):7.928918657272288
        Encrypted:false
        SSDEEP:24576:Qi4th4HdHtaqrbvYfCxkRPaGynuJ4Bk0xdh1HVsx+aV3gyGw:P4tCvaqx0Ht+Bk0DNswq3g8
        MD5:0F129AA97048F7EC0557B211349A2CE0
        SHA1:B597185C94FAC60CD7E25DB83BFB39ED07409289
        SHA-256:FCF3B27FDC54C53A1F7510ABF8BDF748BD3199813D0294738FEBA29C7C1054D1
        SHA-512:0780847D48DDF9336633665560185E58C60BFD516D7CEB2139DE897C526E3D23236667A7BCC199009C37E1D8B153C40377D9717C51F97450967297F9D3BA759A
        Malicious:true
        Antivirus:
        • Antivirus: Joe Sandbox ML, Detection: 100%
        • Antivirus: Virustotal, Detection: 26%, Browse
        Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[w................0......~........... ........@.. ....................................@.....................................O.......xz........................................................................... ............... ..H............text...4.... ...................... ..`.rsrc...xz.......|..................@..@.reloc...............Z..............@..B........................H.......$&...............>...............................................0..+....... .......+..(...........X...2.(.........&..*.........''.......0..H.......(....o.....+!..(......r...p .......o....&..&....(....-...........o.....*.........+...........9.......0..U.......r...prS..prW..p(....(....rY..p ............%.(....(.....o....t.....s....%.o....o....*....0..Z.......( ...rc..po!....s"....s#....o$......o%.....o&....o'.......io(.......,..o.....o)...s*...z.*..........-C..........
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe:Zone.Identifier
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):26
        Entropy (8bit):3.95006375643621
        Encrypted:false
        SSDEEP:3:ggPYV:rPYV
        MD5:187F488E27DB4AF347237FE461A079AD
        SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
        SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
        SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
        Malicious:true
        Preview: [ZoneTransfer]....ZoneId=0

        Static File Info

        General

        File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
        Entropy (8bit):7.928918657272288
        TrID:
        • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
        • Win32 Executable (generic) a (10002005/4) 49.78%
        • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
        • Generic Win/DOS Executable (2004/3) 0.01%
        • DOS Executable Generic (2002/1) 0.01%
        File name:Peixoto - QUOTATION LIST.exe
        File size:1203200
        MD5:0f129aa97048f7ec0557b211349a2ce0
        SHA1:b597185c94fac60cd7e25db83bfb39ed07409289
        SHA256:fcf3b27fdc54c53a1f7510abf8bdf748bd3199813d0294738feba29c7c1054d1
        SHA512:0780847d48ddf9336633665560185e58c60bfd516d7ceb2139de897c526e3d23236667a7bcc199009c37e1d8b153c40377d9717c51f97450967297f9d3ba759a
        SSDEEP:24576:Qi4th4HdHtaqrbvYfCxkRPaGynuJ4Bk0xdh1HVsx+aV3gyGw:P4tCvaqx0Ht+Bk0DNswq3g8
        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[w................0......~........... ........@.. ....................................@................................

        File Icon

        Icon Hash:b296d2c2a2868682

        Static PE Info

        General

        Entrypoint:0x4efa2e
        Entrypoint Section:.text
        Digitally signed:false
        Imagebase:0x400000
        Subsystem:windows gui
        Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
        DLL Characteristics:NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
        Time Stamp:0xAEA5775B [Mon Nov 6 22:59:39 2062 UTC]
        TLS Callbacks:
        CLR (.Net) Version:v4.0.30319
        OS Version Major:4
        OS Version Minor:0
        File Version Major:4
        File Version Minor:0
        Subsystem Version Major:4
        Subsystem Version Minor:0
        Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744

        Entrypoint Preview

        Instruction
        jmp dword ptr [00402000h]
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al

        Data Directories

        NameVirtual AddressVirtual Size Is in Section
        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IMPORT0xef9dc0x4f.text
        IMAGE_DIRECTORY_ENTRY_RESOURCE0xf00000x37a78.rsrc
        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
        IMAGE_DIRECTORY_ENTRY_BASERELOC0x1280000xc.reloc
        IMAGE_DIRECTORY_ENTRY_DEBUG0xef9c00x1c.text
        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

        Sections

        NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
        .text0x20000xeda340xedc00False0.99087720163data7.99870340819IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
        .rsrc0xf00000x37a780x37c00False0.510588915359data7.04584846576IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
        .reloc0x1280000xc0x200False0.044921875data0.101910425663IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

        Resources

        NameRVASizeTypeLanguageCountry
        RT_ICON0xf02000xf9eePNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
        RT_ICON0xffc000x10828dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 1510015233, next used block 1359020289
        RT_ICON0x1104380x94a8data
        RT_ICON0x1198f00x5488data
        RT_ICON0x11ed880x4228dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 0, next used block 16777216
        RT_ICON0x122fc00x25a8data
        RT_ICON0x1255780x10a8data
        RT_ICON0x1266300x988data
        RT_ICON0x126fc80x468GLS_BINARY_LSB_FIRST
        RT_GROUP_ICON0x1274400x84data
        RT_VERSION0x1274d40x3a4data
        RT_MANIFEST0x1278880x1eaXML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

        Imports

        DLLImport
        mscoree.dll_CorExeMain

        Version Infos

        DescriptionData
        Translation0x0000 0x04b0
        LegalCopyrightCopyright (C) 2014-2021
        Assembly Version3.1.1.0
        InternalNamenow-ConsoleApp13.exe
        FileVersion3.1.1.0
        CompanyNameTelegram FZ-LLC
        LegalTrademarks
        CommentsTelegram Desktop
        ProductNameTelegram Desktop
        ProductVersion3.1.1.0
        FileDescriptionTelegram Desktop
        OriginalFilenamenow-ConsoleApp13.exe

        Network Behavior

        Snort IDS Alerts

        TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
        10/08/21-16:09:58.908995TCP2025019ET TROJAN Possible NanoCore C2 60B497514557192.168.2.7185.222.57.149
        10/08/21-16:10:06.551810TCP2025019ET TROJAN Possible NanoCore C2 60B497524557192.168.2.7185.222.57.149
        10/08/21-16:10:13.338507TCP2025019ET TROJAN Possible NanoCore C2 60B497734557192.168.2.7185.222.57.149
        10/08/21-16:10:18.369904TCP2025019ET TROJAN Possible NanoCore C2 60B497794557192.168.2.7185.222.57.149
        10/08/21-16:10:24.464828TCP2025019ET TROJAN Possible NanoCore C2 60B497804557192.168.2.7185.222.57.149
        10/08/21-16:10:30.480115TCP2025019ET TROJAN Possible NanoCore C2 60B497814557192.168.2.7185.222.57.149
        10/08/21-16:10:38.372617TCP2025019ET TROJAN Possible NanoCore C2 60B497824557192.168.2.7185.222.57.149
        10/08/21-16:10:44.482585TCP2025019ET TROJAN Possible NanoCore C2 60B497834557192.168.2.7185.222.57.149
        10/08/21-16:10:50.550682TCP2025019ET TROJAN Possible NanoCore C2 60B498014557192.168.2.7185.222.57.149
        10/08/21-16:10:56.622820TCP2025019ET TROJAN Possible NanoCore C2 60B498134557192.168.2.7185.222.57.149
        10/08/21-16:11:01.719619TCP2025019ET TROJAN Possible NanoCore C2 60B498144557192.168.2.7185.222.57.149
        10/08/21-16:11:07.735436TCP2025019ET TROJAN Possible NanoCore C2 60B498154557192.168.2.7185.222.57.149
        10/08/21-16:11:13.858199TCP2025019ET TROJAN Possible NanoCore C2 60B498164557192.168.2.7185.222.57.149

        Network Port Distribution

        TCP Packets

        TimestampSource PortDest PortSource IPDest IP
        Oct 8, 2021 16:09:58.445188046 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.467081070 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:58.467223883 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.908994913 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.948772907 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:58.959141016 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.981297970 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:58.999886036 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.082442045 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087639093 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087661028 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087677956 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087693930 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087722063 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087759018 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111536026 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111576080 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111620903 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111644983 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111663103 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111685038 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111686945 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111706018 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111715078 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111731052 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111737013 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111748934 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111763954 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133198023 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133235931 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133256912 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133275986 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133299112 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133315086 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133321047 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133342028 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133346081 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133363008 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133366108 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133383989 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133404016 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133405924 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133424997 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133440018 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133444071 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133466959 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133486986 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133491039 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133506060 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133524895 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133527994 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133541107 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133572102 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155138016 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155175924 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155200958 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155220032 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155237913 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155256033 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155275106 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155298948 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155323029 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155345917 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155363083 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155365944 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155390024 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155390978 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155394077 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155396938 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155414104 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155436039 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155456066 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155457973 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155482054 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155504942 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155504942 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155528069 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155560017 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155567884 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155584097 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155594110 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155610085 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155698061 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155734062 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155765057 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155786991 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155800104 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155810118 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155831099 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155853033 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155855894 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155874014 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155893087 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155908108 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155914068 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155935049 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155941963 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155960083 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155982018 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155982018 CEST455749751185.222.57.149192.168.2.7

        Code Manipulations

        Statistics

        Behavior

        Click to jump to process

        System Behavior

        General

        Start time:16:09:09
        Start date:08/10/2021
        Path:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        Wow64 process (32bit):true
        Commandline:'C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe'
        Imagebase:0x20000
        File size:1203200 bytes
        MD5 hash:0F129AA97048F7EC0557B211349A2CE0
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:.Net C# or VB.NET
        Yara matches:
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        Reputation:low

        General

        Start time:16:09:53
        Start date:08/10/2021
        Path:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Wow64 process (32bit):false
        Commandline:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Imagebase:0x10000
        File size:1203200 bytes
        MD5 hash:0F129AA97048F7EC0557B211349A2CE0
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Antivirus matches:
        • Detection: 100%, Joe Sandbox ML
        • Detection: 26%, Virustotal, Browse
        Reputation:low

        General

        Start time:16:09:53
        Start date:08/10/2021
        Path:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Wow64 process (32bit):true
        Commandline:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Imagebase:0xeb0000
        File size:1203200 bytes
        MD5 hash:0F129AA97048F7EC0557B211349A2CE0
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:.Net C# or VB.NET
        Yara matches:
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.505641453.00000000046D8000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, Author: Joe Security
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, Author: Florian Roth
        Reputation:low

        Disassembly

        Code Analysis

        Reset < >